Home

Description

Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0.

PUBLISHED Reserved 2026-04-22 | Published 2026-04-22 | Updated 2026-04-22 | Assigner samsung.tv_appliance




MEDIUM: 6.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Problem types

CWE-1284 Improper validation of specified quantity in input

Product status

Default status
unaffected

1.30.0
affected

References

github.com/Samsung/ONE/pull/16481

cve.org (CVE-2026-6839)

nvd.nist.gov (CVE-2026-6839)

Download JSON